{"id":11739,"date":"2025-06-23T21:02:07","date_gmt":"2025-06-23T21:02:07","guid":{"rendered":"https:\/\/usaontheweb.com\/clone1\/wordpress-motors-theme-flaw-mass-exploited-to-hijack-admin-accounts\/"},"modified":"2025-06-23T21:02:07","modified_gmt":"2025-06-23T21:02:07","slug":"wordpress-motors-theme-flaw-mass-exploited-to-hijack-admin-accounts","status":"publish","type":"post","link":"https:\/\/usaontheweb.com\/clone1\/wordpress-motors-theme-flaw-mass-exploited-to-hijack-admin-accounts\/","title":{"rendered":"WordPress Motors theme flaw mass-exploited to hijack admin accounts"},"content":{"rendered":"<p>WordPress <\/p>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"Wordpress Hacker\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2025\/03\/08\/hacker-parking.jpg\" width=\"1600\"><\/p>\n<p>Hackers are exploiting a critical privilege escalation vulnerability in the WordPress theme &#8220;Motors&#8221; to hijack administrator accounts and gain complete control of a targeted site.<\/p>\n<p>The malicious activity was spotted by Wordfence, which had warned last month about the severity of the flaw, tracked under CVE-2025-4322, urging users to upgrade immediately.<\/p>\n<p>Motors, developed by StylemixThemes, is a WordPress theme popular among automotive-related websites. It has 22,460 sales on the EnvatoMarket and is backed by an active community of users.<\/p>\n<p>The privilege escalation vulnerability was discovered on May 2, 2025, and first reported by Wordfence on May 19, impacting all versions before and including 5.6.67.<\/p>\n<p>The flaw arises from an improper user identity validation during password updating, allowing unauthenticated attackers to change administrator passwords at will.<\/p>\n<p>StylemixThemes released Motors version 5.6.68, which addresses CVE-2025-4322, on May 14, 2025, but many users failed to apply the update by Wordfence&#8217;s disclosure and got exposed to elevated exploitation risk.<\/p>\n<p>As Wordfence confirms in a new writeup, the attacks began on May 20, only a day after they publicly disclosed the details. Wide-scale attacks were observed by June 7, 2025, with Wordfence reporting blocking 23,100 attempts against its customers.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Wordpress Daily attack volumes\" height=\"551\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/June\/exploit-volume(1).jpg\" width=\"818\"><figcaption><strong>Daily attack volumes<\/strong><br \/><em>Source: Wordfence<\/em><\/figcaption><\/figure>\n<\/div>\n<h2>WordPress Attack process and signs of breach<\/h2>\n<p>The vulnerability is in the Motors theme&#8217;s &#8220;Login Register&#8221; widget, including password recovery functionality.<\/p>\n<p>The attacker first locates the URL where this widget is placed by probing \/login-register, \/account, \/reset-password, \/signin, etc., with specially crafted POST requests until they get a hit.<\/p>\n<p>The request contains invalid UTF-8 characters in a malicious &#8216;hash_check&#8217; value, causing the hash comparison in the password reset logic to succeed incorrectly.<\/p>\n<p>The POST body contains a &#8216;stm_new_password&#8217; value that resets the user password, targeting user IDs that typically correspond to administrator users.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Wordpress Example requests from the attacks\" height=\"376\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/June\/example-requests.jpg\" width=\"731\"><figcaption><strong>Example requests from the attacks<\/strong><br \/><em>Source: Wordfence<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Attacker-set passwords observed in the attacks so far include:\u00a0<\/p>\n<ul>\n<li>Testtest123!@#<\/li>\n<li>rzkkd$SP3znjrn<\/li>\n<li>Kurd@Kurd12123<\/li>\n<li>owm9cpXHAZTk<\/li>\n<li>db250WJUNEiG<\/li>\n<\/ul>\n<p>Once access is gained, the attackers log into the WordPress dashboard as administrators and create new admin accounts for persistence.<\/p>\n<p>The sudden appearance of such accounts combined with existing administrators being locked out (passwords no longer working) are signs of CVE-2025-4322 exploitation.<\/p>\n<p>Wordfence has also listed several IP addresses that launch these attacks in the report, which WordPress site owners are recommended to put on their block list.<\/p>\n<div>\n<p>\n            <img decoding=\"async\" alt=\"Wordpress Tines Needle\" src=\"https:\/\/www.bleepstatic.com\/c\/t\/tines\/tines-needle.jpg\" previous-src=\"https:\/\/www.bleepstatic.com\/c\/t\/tines\/tines-needle.jpg\">\n    <\/p>\n<div>\n<h2>WordPress Why IT teams are ditching manual patch management<\/h2>\n<p>Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.<\/p>\n<p>In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work &#8212; no complex scripts required.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>WordPress Hackers are exploiting a critical privilege escalation vulnerability in the WordPress theme &#8220;Motors&#8221; to hijack administrator accounts and gain<\/p>\n","protected":false},"author":7282,"featured_media":11740,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1166],"tags":[],"class_list":["post-11739","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-website"],"_links":{"self":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts\/11739","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/users\/7282"}],"replies":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/comments?post=11739"}],"version-history":[{"count":0,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts\/11739\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/media\/11740"}],"wp:attachment":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/media?parent=11739"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/categories?post=11739"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/tags?post=11739"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}